|
EH-Net
|
|
May 24, 2013, 06:37:37 AM
|
Show Posts
|
|
Pages: 1 [2] 3 4 ... 22
|
|
24
|
Resources / Tools / Re: Really, really good LFI list
|
on: March 29, 2010, 01:10:12 PM
|
|
exactly... once you find your LFI you can use a bash script with curl to iterate through this list and download all files it can access.
Good times.
|
|
|
|
|
25
|
Resources / Tools / Re: Really, really good LFI list
|
on: March 29, 2010, 09:43:05 AM
|
|
thanks Anquilas,
Correct, any server side code that will read files on the webserver and display them is an LFI.
The list contains the juicy stuff you want to get when you compromise a server this way.
It also serves as just a nice list to get when you pop a box in general =)
|
|
|
|
|
27
|
Ethical Hacking Discussions and Related Certifications / Social Engineering / Re: Practicing social engineering
|
on: March 26, 2010, 03:05:24 AM
|
|
For physical SE this is quite controversial, and i dont practice it personally, but i know people who needed more SE cajonesand practiced reflective SE at ponzi-scheme meetups, scientology recruitments, local debate clubs, auctions, etc.
Just make sure your actions do not hurt anyone (monetarily,physically, and emotionally) ...
|
|
|
|
|
29
|
Resources / Tools / Burp Proxy to XML Tool release: BURP2XML
|
on: March 24, 2010, 03:54:09 PM
|
With the incorporation of Burp Suite Professional into our audit processes, we discovered that there was not an easy method to extract results from Burp’s session file without having to manually re-run Burp. In order to automate this process, we have developed a standalone Python script to process Burp’s session files into XML, and have released it under the GPLv3 License here burp2xml.pyXML will allow you to pull out all types of useful data and feed it to other tools or make scripting an output report much easier. We will be blogging about tips to use this pretty soon, let us know what you think.
|
|
|
|
|
30
|
Features / Opinions / Re: Opinions on Webgoat
|
on: March 22, 2010, 05:13:05 PM
|
|
Dieter,
To specifically answer your question, yes i think a write-up on working your way through the Webgoat vulnerabilities would be useful to many new comers to the site, even if it's just your experiences.
Plus something i know for a fact is most people learn well by practical exposure, and the best way to retain the knowledge is teaching it to others =)
|
|
|
|
|
Loading...
|